package land_register;

import java.io.IOException;
import java.io.PrintWriter;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import org.json.JSONObject;

import DB.DB_connection_pool;


public class Login_servlet extends HttpServlet {
	private static final long serialVersionUID = 1L;

	protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		// TODO Auto-generated method stub
		doPost(request,response);
	}


	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		// TODO Auto-generated method stub
		PrintWriter out = response.getWriter();
		
		String phone_email = request.getParameter("user_account");
        String password = request.getParameter("password");		
		
        
        String user_account="";   //账户
        
        //String select_phone_email="select * from land_table where user_password in (select user_password from land_table where user_telephone='"+phone_email+"' or user_email='"+phone_email+"')";
        String select_phone_email = "select * from land_table where user_password = '"+password+"' and (user_telephone = '"+phone_email+"' or user_email = '"+phone_email+"')";
        
        try {
			Connection conn = DB_connection_pool.data_pool.getConnection();
			PreparedStatement ps_select= conn.prepareStatement(select_phone_email);
			ResultSet rs = ps_select.executeQuery();
			
			
			JSONObject jsonObj = new JSONObject();
			if(rs.next()){    //说明手机或邮箱账号存在
				user_account=rs.getString("user_account");
				jsonObj.put("user_account", user_account);
				jsonObj.put("result", true);
			}else{
				jsonObj.put("result", false);
			}
		
			out.print(jsonObj.toString());
			
			rs.close();
			ps_select.close();
			out.close();
			conn.close();
			
		} catch (SQLException e) {
			// TODO Auto-generated catch block
			e.printStackTrace();
		}   
        
		
	}

}
